Eunifi Privacy Policy
Effective Date: Januar 6, 2026
1. Introduction
This Privacy Policy (“Policy”) describes how Ramsey Theory Group (“RTG,” “we,” “us,” or “our”), the operator of the Eunifi platform available at eunifi.com (the “Platform” or “Service”), collects, uses, discloses, and safeguards information about individuals who interact with the Service.
Eunifi is a software-as-a-service platform designed for automotive dealerships and their authorized users. It provides identity verification, fraud detection, customer onboarding, and related dealer operations tooling.
This Policy applies to:
- Dealer Users: Dealership employees, owners, administrators, and authorized agents who access the Platform on behalf of a dealership (“Dealer Customer”).
- Consumers: Individuals (vehicle buyers, lessees, co-applicants, trade-in customers, service customers, or other end users) whose personal information is submitted to or processed through the Platform in connection with a transaction or prospective transaction with a Dealer Customer.
- Website Visitors: Anyone who visits eunifi.com or our marketing properties.
Important role distinction. When a Consumer’s personal information is submitted to the Platform by a Dealer Customer (for example, during identity verification or fraud screening at a dealership), the Dealer Customer is the “business” or controller of that personal information, and Eunifi acts as a “service provider” or processor under applicable law. The Dealer Customer’s own privacy notices, consents, and disclosures govern its collection of that information. This Policy describes RTG’s own practices with respect to information we collect directly and the limited ways we may use Consumer information across the Service.
If you are a Consumer with questions about how a specific dealership uses your information, please contact that dealership directly.
2. Information We Collect
We collect the following categories of personal information. The specific data fields collected depend on which features of the Platform are used and what a Dealer Customer has configured.
2.1 Information You or a Dealer Provides
Account and Dealer User information:
- Name, business email, phone number, job title, and dealership affiliation
- Login credentials (passwords are stored using one-way salted hashing)
- Profile preferences, role and permission settings
- Communications with Eunifi support
Consumer information submitted through the Platform:
- Full legal name, date of birth, residential address, prior addresses
- Government-issued identification document images (driver’s license, passport, state ID, military ID) including the document number, issue date, expiration date, issuing authority, and the photograph printed on the document
- Selfie or “liveness” capture used to confirm that the person presenting the ID matches the ID
- Last four digits of Social Security Number (and, where required by a dealer’s red-flag program, full SSN)
- Phone number, email address, employment information
- Vehicle-of-interest information, trade-in information, and other transaction context
- Co-applicant information, if applicable
- Signed disclosures, attestations, and consents collected at the point of capture
Biometric and biometric-derived data:
When a Dealer Customer uses identity verification features that include biometric matching (for example, our Jumio-powered biometric duplicate handling, selfie-to-ID match, or liveness detection), the following may be processed:
- A selfie or video of the Consumer’s face
- A facial geometry template or other biometric identifier derived from the selfie and the photograph on the ID
- A match score and pass/fail result
- A hashed or vectorized representation used for duplicate detection across the Platform
Biometric data is handled in accordance with Section 9 (Biometric Information) below.
2.2 Information Collected Automatically
When Dealer Users or Website Visitors access our Service, we automatically collect:
- IP address, approximate geolocation derived from IP, device identifiers, browser type and version, operating system, and language settings
- Pages or screens viewed, features used, buttons clicked, timestamps, referring URL, and session duration
- Diagnostic, performance, and error data
- Cookie identifiers and similar technology data (see Section 6)
Consumers interacting with embedded Eunifi capture flows (for example, a mobile capture link sent by a dealer) may also have device and session metadata collected to support fraud detection and to evidence that the capture occurred as represented.
2.3 Information From Third Parties
To deliver verification and fraud-detection features, we receive information from:
- Identity verification and biometric service providers (e.g., Jumio): document authenticity results, facial-match scores, liveness results, and verification reason codes
- Fraud and risk providers: red-flag indicators, watchlist matches, and synthetic-identity signals
- Identity data providers: address and identity attribute validation
- OFAC and sanctions screening providers, where the Dealer Customer enables those checks
- Single sign-on / identity providers used by a dealership (e.g., Google Workspace, Microsoft Entra)
- Analytics and infrastructure providers that support the Service
We only use information from third parties to provide, secure, improve, and support the Service.
3. How We Use Personal Information
We use personal information for the following business purposes:
- Operating the Service — authenticating users, provisioning dealerships, processing identity verifications, returning verification results and fraud signals to Dealer Customers, and supporting related workflows such as onboarding and the IDV Quiz.
- Fraud prevention and security — detecting duplicate identities across the Platform (including using a hashed or vectorized biometric representation for the Jumio Biometric Duplicate Handling feature), preventing account takeover, detecting suspicious submissions, and protecting the Service against abuse.
- Compliance — supporting Dealer Customers’ compliance obligations under the FTC Red Flags Rule, the USA PATRIOT Act, OFAC sanctions screening (where enabled), the FTC Safeguards Rule, and applicable state laws.
- Service improvement — measuring feature performance, debugging, and improving accuracy of verification and risk models, in each case using minimized or de-identified data where reasonably practicable.
- Customer support and communications — responding to inquiries, sending service notices, security alerts, and product updates to Dealer Users.
- Marketing to dealerships — sending business-to-business marketing about Eunifi to Dealer Users and prospective dealer accounts. We do not market to Consumers based on Consumer personal information submitted through the Platform.
- Legal and protective purposes — complying with subpoenas, court orders, and other legal process; enforcing our Terms of Service; protecting the rights, property, and safety of RTG, our customers, and the public.
We do not use Consumer personal information collected on behalf of a Dealer Customer to build profiles for cross-context behavioral advertising, to train generally-available AI models, or for any purpose that is not reasonably necessary and proportionate to providing the Service.
4. How We Disclose Personal Information
We disclose personal information only as described below.
- To the Dealer Customer that submitted or is associated with the information. Verification results, fraud signals, and Consumer-submitted data are returned to the dealership that initiated the transaction.
- To service providers and subprocessors that perform functions on our behalf, including cloud hosting, identity verification (e.g., Jumio), biometric matching, OFAC screening, analytics, email delivery, error monitoring, and customer support tooling. Each subprocessor is bound by written contract to use the information only to provide services to us and to maintain appropriate security.
- To affiliates of Ramsey Theory Group that support the operation of Eunifi, under the same protections described in this Policy.
- In connection with a corporate transaction — such as a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy — where personal information may be transferred as a business asset, subject to confidentiality obligations.
- For legal reasons — to comply with applicable law, lawful requests, and legal process; to enforce our agreements; to protect against fraud, security, or technical issues; or to protect the rights, property, or safety of RTG, our users, or others.
- With your consent or at your direction.
We do not sell personal information for money. We do not share Consumer personal information for cross-context behavioral advertising. With respect to Dealer User business-contact information used for our own marketing, see Section 7 for opt-out rights.
5. Legal Bases and Sources
Because RTG generally acts as a service provider to Dealer Customers with respect to Consumer information, the Dealer Customer is responsible for establishing and disclosing the legal basis for its collection of Consumer information. RTG processes that information only under written contract with the Dealer Customer and only for the purposes described in Section 3.
For Dealer User information and website analytics that we collect directly, we rely on our legitimate business interest in operating, securing, and improving the Service, our performance of contracts with Dealer Customers, our compliance with law, and (where required) consent.
6. Cookies and Similar Technologies
eunifi.com and the authenticated Platform use cookies, local storage, and similar technologies to:
- Keep users signed in and maintain session state (strictly necessary)
- Remember preferences (functional)
- Measure traffic, feature usage, and performance (analytics)
We do not use third-party advertising cookies or pixels on the authenticated Platform. On marketing pages, we may use a limited set of analytics and conversion-measurement tools. You can control cookies through your browser settings, and where required by law, we present a cookie banner to manage non-essential cookies.
7. Your Privacy Rights
Subject to applicable law and verification of your identity, you may have the following rights regarding personal information that RTG controls.
California (CCPA/CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other US state privacy laws. Depending on your state of residence, you may have the right to:
- Know / access — request the categories and specific pieces of personal information we have collected about you.
- Delete — request deletion of personal information we have collected about you.
- Correct — request correction of inaccurate personal information.
- Portability — receive a copy of your personal information in a portable format.
- Opt out of sale or sharing — opt out of the “sale” of personal information or “sharing” for cross-context behavioral advertising. RTG does not sell personal information and does not share it for cross-context behavioral advertising.
- Opt out of certain profiling — opt out of profiling in furtherance of decisions producing legal or similarly significant effects, where applicable.
- Limit use of sensitive personal information — direct us to limit the use of sensitive personal information to purposes necessary to perform the Service.
- Non-discrimination — not be discriminated against for exercising your rights.
Authorized agents. You may use an authorized agent to make a request on your behalf, subject to verification.
Appeals. If we decline your request, you may appeal by replying to our response or contacting us at the address in Section 14. We will respond to appeals within the time required by the law of your state.
Consumer information submitted by dealerships. Because RTG acts as a service provider for Consumer information submitted by Dealer Customers, the most direct way to exercise rights regarding that information is to contact the dealership that collected it. We will assist Dealer Customers in responding to verified Consumer requests as required by law.
Submitting a request. To submit a request directly to RTG, email [email protected] with the subject line “Privacy Rights Request” and a description of your request. We will verify your identity using information already in our possession before fulfilling the request. We aim to respond within 45 days, with one 45-day extension where reasonably necessary.
8. Sensitive Personal Information
Some information processed through the Platform constitutes “sensitive personal information” or a “specified category” under state privacy laws, including:
- Government identifier information (driver’s license, state ID, passport numbers; full or partial SSN)
- Precise geolocation, in limited cases
- Biometric information used for the purpose of uniquely identifying a Consumer
We use sensitive personal information solely to perform the verification, fraud detection, and compliance functions that the Dealer Customer has requested, to maintain quality and safety of the Service, and as otherwise permitted by law. We do not use it to infer characteristics about a Consumer for advertising, and we do not disclose it for purposes that are not strictly necessary to the Service.
9. Biometric Information
Eunifi processes biometric identifiers and biometric information (collectively, “Biometric Data”) to perform identity verification, prevent fraud, and detect duplicate enrollments. This Section sets out our practices, including those required by laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington’s biometric statute (RCW 19.375), the Washington My Health My Data Act, the New York City biometric identifier ordinance, and similar laws.
What we collect. When biometric verification features are enabled by a Dealer Customer, we (or our verification subprocessor) collect:
- A selfie or short video of the Consumer
- The photograph printed on the government-issued ID
- A facial geometry template derived from those images
- A hashed or vectorized representation used to detect duplicates
Purposes. We use Biometric Data only to:
- Confirm that the person presenting an ID is the same person depicted on the ID
- Detect attempts to enroll under a different identity, including for the Red Flags and Web Submission Duplicate Detection features
- Prevent fraud, impersonation, and identity theft
- Meet the Dealer Customer’s compliance obligations
Consent. Biometric Data is processed only after written, informed consent is obtained from the Consumer at the point of capture. The consent disclosure identifies RTG and the verification subprocessor, the categories of Biometric Data collected, the purpose, the duration of retention, and the destruction schedule.
No sale or licensing. We do not sell, lease, trade, or otherwise profit from Biometric Data, and we do not disclose Biometric Data except (a) to the Dealer Customer that initiated the verification, (b) to our verification and biometric subprocessors strictly to perform the verification, (c) as required by law or valid legal process, or (d) with the Consumer’s separate written consent.
Retention and destruction. Biometric Data is retained only as long as needed to fulfill the purpose for which it was collected, and in no event longer than:
- Raw biometric images (selfie, ID photograph): deleted within 30 days of the completion of the verification, except where (i) the verification is part of an ongoing fraud investigation or (ii) the Dealer Customer requests retention for evidentiary purposes, in which case retention is extended only as long as reasonably necessary.
- Facial geometry templates and duplicate-detection vectors: retained for the lifetime of the Consumer’s association with a Dealer Customer plus up to three (3) years thereafter, or as required to perform duplicate detection across the Platform, after which they are permanently destroyed.
- Match results, decision metadata, and audit logs: retained per Section 11 (Retention) and the separate Retention Policy.
Biometric Data is destroyed when (a) the initial purpose has been satisfied, (b) the applicable retention period has elapsed, or (c) the Consumer exercises a valid deletion right that we are not legally required to deny — whichever occurs first.
Storage and security. Biometric Data is encrypted in transit and at rest, stored in a manner that is the same as or more protective than the manner in which we store other confidential and sensitive information, and access is restricted to a limited number of authorized personnel under role-based access controls.
10. Children’s Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact [email protected] so that we can take appropriate action.
Where a dealership lawfully transacts with a co-applicant or signer who is a minor, the Dealer Customer is responsible for obtaining the consents required by law.
11. Data Retention
We retain personal information only as long as reasonably necessary to fulfill the purposes described in this Policy, to comply with our legal and contractual obligations, to resolve disputes, and to enforce our agreements. Specific retention periods are set out in our separate Eunifi Data Retention Policy, which is incorporated into this Policy by reference. In summary:
- Verification results and audit logs are retained for the length of the Dealer Customer’s subscription plus a defined post-termination period to support compliance and audit obligations.
- Raw documents and biometric images are deleted within 30 days of verification, subject to the exceptions described above.
- Account and Dealer User records are retained while the account is active and for a defined period after termination.
- Backups are subject to a separate, shorter retention cycle.
When retention periods expire, personal information is securely destroyed or irreversibly de-identified.
12. Security
We maintain a written information security program designed to comply with the FTC Safeguards Rule and industry best practices. Controls include:
- Encryption of personal information in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
- Role-based access controls, least-privilege provisioning, and mandatory multi-factor authentication for administrative access
- Segregation of production and non-production environments; no real Consumer personal information in non-production systems without strict controls
- Continuous logging and monitoring, vulnerability management, and annual third-party security testing
- Vendor risk management for all subprocessors that handle personal information
- Documented incident response procedures, including notification of affected Dealer Customers and, where applicable, Consumers, in accordance with law
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work continuously to reduce risk.
13. Data Transfers and Location
Personal information is processed and stored on infrastructure located in the United States. Some subprocessors may process limited data from other locations to provide support, monitoring, or fraud-detection services. We do not transfer Consumer personal information outside the United States except as required to deliver the verification subprocessor’s services, in which case the transfer is governed by contractual safeguards.
14. Contact Us
For privacy questions, rights requests, or other inquiries:
- Email: [email protected]
- Mail: Ramsey Theory Group — Attn: Privacy Office, 2125 Center Avenue, Fort Lee, NJ 07024, United States
- Web: eunifi.com/privacy
We will respond to legitimate inquiries within the time required by applicable law.
15. Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date at the top of this Policy indicates when it was last revised. Material changes will be communicated by posting a notice on eunifi.com, by emailing Dealer Customers, or by other reasonable means. Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the changes, to the extent permitted by law.

